CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2012-4892

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in FlatnuX CMS 2012-03.08 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title_en, (2) summary_en, or (3) body_en parameter in a submitnews action to the news module, a different vulnerability than CVE-2012-4890. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2789

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the avi_read_packet function in libavformat/avidec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to a large number of vector coded coefficients (num_vec_coeffs).

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2796

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the vc1_decode_frame function in libavcodec/vc1dec.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknown impact and attack vectors, related to inconsistencies in "coded slice positions and interlacing" that trigger "out of array writes."

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2803

    Last Modified: 11 Apr 2025

    Double free vulnerability in the mpeg_decode_frame function in libavcodec/mpeg12.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, has unknown impact and attack vectors, related to resetting the data size value.

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2804

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in libavcodec/indeo3.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.5 has unknown impact and attack vectors, related to "reallocation code" and the luma height and width.

    Published: 10 Sept 2012
    6
    Medium

    CVE-2012-4404

    Last Modified: 11 Apr 2025

    security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a member of the group.

    Published: 10 Sept 2012
    4.3
    Medium

    CVE-2012-4891

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in fw/index2.do in ManageEngine Firewall Analyzer 7.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter, a different vector than CVE-2012-4889. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2795

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in libavcodec/wmalosslessdec.c in FFmpeg before 0.11 have unknown impact and attack vectors related to (1) size of "mclms arrays," (2) "a get_bits(0) in decode_ac_filter," and (3) "too many bits in decode_channel_residues()."

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2772

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the ff_rv34_decode_frame function in libavcodec/rv34.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to "width/height changing with frame threading."

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2788

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the avi_read_packet function in libavformat/avidec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to an "out of array read" when a "packet is shrunk."

    Published: 10 Sept 2012
    10
    Critical

    CVE-2012-2793

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the lag_decode_zero_run_line function in libavcodec/lagarith.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors related to "too many zeros."

    Published: 10 Sept 2012
    4.3
    Medium

    CVE-2012-4890

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in FlatnuX CMS 2011 08.09.2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) comment to the news, (2) title to the news, or (3) the folder names in a gallery.

    Published: 10 Sept 2012
    6.5
    Medium

    CVE-2012-0727

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 10 Sept 2012
    4
    Medium

    CVE-2012-2185

    Last Modified: 11 Apr 2025

    IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to obtain sensitive information via unspecified vectors.

    Published: 10 Sept 2012
    4.3
    Medium

    CVE-2012-3326

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 10 Sept 2012
    6.8
    Medium

    CVE-2012-0714

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 10 Sept 2012
    6.5
    Medium

    CVE-2012-0728

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 10 Sept 2012
    6.5
    Medium

    CVE-2012-0747

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 10 Sept 2012
    6.8
    Medium

    CVE-2012-2183

    Last Modified: 11 Apr 2025

    Session fixation vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack web sessions via unspecified vectors.

    Published: 10 Sept 2012
    6.8
    Medium

    CVE-2012-2184

    Last Modified: 11 Apr 2025

    Session fixation vulnerability in IBM Maximo Asset Management 7.1 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack web sessions via unspecified vectors.

    Published: 10 Sept 2012
    3.5
    Low

    CVE-2012-0746

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 10 Sept 2012
    4.3
    Medium

    CVE-2012-3313

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 10 Sept 2012
    6.8
    Medium

    CVE-2012-3547

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2.1.10 through 2.1.12, when using TLS-based EAP methods, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via a long "not after" timestamp in a client certificate.

    Published: 10 Sept 2012
    4.3
    Medium

    CVE-2011-4942

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in admin/configuration.php in Geeklog before 1.7.1sr1 allow remote attackers to inject arbitrary web script or HTML via the (1) subgroup or (2) conf_group parameters. NOTE: this vulnerability might require a user-assisted attack or a bypass of a CSRF protection mechanism.

    Published: 9 Sept 2012
    4.3
    Medium

    CVE-2011-5159

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/configuration.php in Geeklog before 1.7.1sr1 allows remote attackers to inject arbitrary web script or HTML via the sub_group parameter, a different vulnerability than CVE-2011-4942.

    Published: 9 Sept 2012
    4.3
    Medium

    CVE-2011-5160

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in setup.php in OpenEMR 4 allows remote attackers to inject arbitrary web script or HTML via the site parameter.

    Published: 9 Sept 2012
    6.8
    Medium

    CVE-2011-5161

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in the patient photograph functionality in OpenEMR 4 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the patient directory under documents/.

    Published: 9 Sept 2012
    5
    Medium

    CVE-2012-1152

    Last Modified: 11 Apr 2025

    Multiple format string vulnerabilities in the error reporting functionality in the YAML::LibYAML (aka YAML-LibYAML and perl-YAML-LibYAML) module 0.38 for Perl allow remote attackers to cause a denial of service (process crash) via format string specifiers in a (1) YAML stream to the Load function, (2) YAML node to the load_node function, (3) YAML mapping to the load_mapping function, or (4) YAML sequence to the load_sequence function.

    Published: 9 Sept 2012
    6.8
    Medium

    CVE-2012-1578

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allow remote attackers to hijack the authentication of users with the block permission for requests that (1) block a user via a request to the Block module or (2) unblock a user via a request to the Unblock module.

    Published: 9 Sept 2012
    5
    Medium

    CVE-2012-1579

    Last Modified: 11 Apr 2025

    The resource loader in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 includes private data such as CSRF tokens in a JavaScript file, which allows remote attackers to obtain sensitive information.

    Published: 9 Sept 2012
    6.8
    Medium

    CVE-2012-1580

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Special:Upload in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to hijack the authentication of unspecified victims for requests that upload files.

    Published: 9 Sept 2012
    5
    Medium

    CVE-2012-1581

    Last Modified: 11 Apr 2025

    MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 uses weak random numbers for password reset tokens, which makes it easier for remote attackers to change the passwords of arbitrary users.

    Published: 9 Sept 2012
    2.1
    Low

    CVE-2012-1648

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Cool Aid module before 6.x-1.9 for Drupal allows remote authenticated users with the administer coolaid permission to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Sept 2012
    7.5
    High

    CVE-2012-1911

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in PHP Address Book 6.2.12 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) to_group parameter to group.php or (2) id parameter to vcard.php. NOTE: the edit.php vector is already covered by CVE-2008-2565.

    Published: 9 Sept 2012
    7.5
    High

    CVE-2012-2115

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in interface/login/validateUser.php in OpenEMR 4.1.0 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the u parameter.

    Published: 9 Sept 2012
    6.8
    Medium

    CVE-2012-2316

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in servlet/admin/AuthServlet.java in OpenKM 5.1.7 and other versions before 5.1.8-2 allows remote attackers to hijack the authentication of administrators for requests that execute arbitrary code via the script parameter to admin/scripting.jsp.

    Published: 9 Sept 2012
    5
    Medium

    CVE-2012-4885

    Last Modified: 11 Apr 2025

    The wikitext parser in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to cause a denial of service (infinite loop) via certain input, as demonstrated by the padleft function.

    Published: 9 Sept 2012
    4.3
    Medium

    CVE-2012-1582

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the wikitext parser in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 allows remote attackers to inject arbitrary web script or HTML via a crafted page with "forged strip item markers," as demonstrated using the CharInsert extension.

    Published: 9 Sept 2012
    4.9
    Medium

    CVE-2012-1649

    Last Modified: 11 Apr 2025

    Cool Aid module before 6.x-1.9 for Drupal does not enforce access restrictions, which allows remote authenticated users with the administer coolaid permission to modify arbitrary pages via unspecified vectors.

    Published: 9 Sept 2012
    4.3
    Medium

    CVE-2012-1912

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in preferences.php in PHP Address Book 7.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the from parameter. NOTE: the index.php vector is already covered by CVE-2008-2566.

    Published: 9 Sept 2012
    4
    Medium

    CVE-2012-2315

    Last Modified: 11 Apr 2025

    admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remote authenticated users to assign administrator privileges to arbitrary users via the userEdit action.

    Published: 9 Sept 2012
    7.5
    High

    CVE-2012-0254

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the HMIWeb Browser HSCDSPRenderDLL ActiveX control in Honeywell Process Solutions (HPS) Experion R2xx, R30x, R31x, and R400.x; Honeywell Building Solutions (HBS) Enterprise Building Manager R400 and R410.1; and Honeywell Environmental Combustion and Controls (ECC) SymmetrE R410.1 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 8 Sept 2012
    6.9
    Medium

    CVE-2012-1666

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in VMware Tools in VMware Workstation before 8.0.4, VMware Player before 4.0.4, VMware Fusion before 4.1.2, VMware View before 5.1, and VMware ESX 4.1 before U3 and 5.0 before P03 allows local users to gain privileges via a Trojan horse tpfc.dll file in the current working directory.

    Published: 8 Sept 2012
    6.9
    Medium

    CVE-2012-3004

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in RealFlex RealWin before 2.1.13, FlexView before 3.1.86, and RealWinDemo before 2.1.13 allow local users to gain privileges via a Trojan horse (1) realwin.dll or (2) keyhook.dll file in the current working directory.

    Published: 8 Sept 2012
    4.3
    Medium

    CVE-2012-3255

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 8.07 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 8 Sept 2012
    6.8
    Medium

    CVE-2012-3256

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in HP Business Availability Center (BAC) 8.07 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 8 Sept 2012
    4.6
    Medium

    CVE-2012-3257

    Last Modified: 11 Apr 2025

    HP Business Availability Center (BAC) 8.07 allows remote authenticated users to hijack web sessions via unspecified vectors.

    Published: 8 Sept 2012
    9.3
    Critical

    CVE-2012-4011

    Last Modified: 11 Apr 2025

    The Cybozu KUNAI application before 2.0.6 for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or execute arbitrary commands, via a crafted web site.

    Published: 8 Sept 2012
    4.3
    Medium

    CVE-2012-4012

    Last Modified: 11 Apr 2025

    The WebView class in the Cybozu KUNAI application before 2.0.6 for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that places this code into a local file associated with a file: URL.

    Published: 8 Sept 2012
    6.9
    Medium

    CVE-2010-5228

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in RealPlayer SP 1.1.5 12.0.0.879 allows local users to gain privileges via a Trojan horse rio500.dll file in the current working directory, as demonstrated by a directory that contains a .avi file. NOTE: some of these details are obtained from third party information.

    Published: 7 Sept 2012